Files
felhom.eu/REPORT-update-night-2026-09-21.md
T
admin da20722e76
gates / gates (push) Successful in 27s
Update night 2026-09-21: Phase 0 and Phase 1 evidence, the drill method, and two instrument fixes
INTERIM CHECKPOINT — evidence off the machine at the end of the phase that produced it (R-320),
not at the end of the session. Phases 2-5 follow in a later commit.

Phase 0, all three mechanisms proven with their controls:
- the fleet floor to 0.261.0 with its declared MinAgent — both demo boxes in 13 s, the hub
  logging `managed floor SERVED ... from declared (golden 0.258.0)`.
- a PRIVATE DRILL CATALOG (admin/app-catalog-drill), so that broken, dummy, cross-repo and
  engine-major edges can be measured without the live catalog ever carrying one. Positive
  control quoted, and two negative controls: the live catalog's main and both real boxes'
  caches unchanged.
- a throwaway image store on the scratch guest, which is what makes an UNATTENDED HOLD
  measurable at all: an edge that PASSES the within-a-major test and still fails.
  CompareImageRefs was proven to order host:port/ references by RUNNING it (4 positive cases
  + 1 negative control), not by reading it.

Phase 1: real within-a-major upstream edges walked on guest 9202 through the product's own
guarded Update, each app seeded and read back through its OWN front door (R-156), with a
per-edge verdict record in 09's shape. `inconclusive` is never collapsed into `failed`.

TWO INSTRUMENT FIXES, both in this repo's own evidence code:
- 00-api-recipe.md said the app page is /app/<n>; it is /apps/<n>, and every call it described
  404s. Corrected, with the session-expiry note that cost the same time.
- unattended-caller.py's follow() read update_phase/updating off the API ENVELOPE, so both were
  always None and EVERY followed update ran to its 900 s timeout and was then recorded
  `timeout` and never-press-again. Fixed before B1 relied on it. R-623.

No controller, agent or hub code was written. The live catalog carries no broken reference.

Gates: repo_gates.py --fast — all 15 OK, exit 0.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-21 21:17:46 +02:00

1.9 KiB
Raw Blame History

REPORT — UPDATE NIGHT, 2026-09-21

The full record is documentation/audits/DRILL-update-night-2026-09-21.md. This file is the session report: what ran, what shipped, what is owed.

(Filled at the end of the run. <…> are placeholders.)

Not done, or changed from the brief

What ran

  • Phase 0 — the fleet floor to 0.261.0 (both demo boxes in 13 s, hub SERVED … from declared); a private drill catalog with a positive and two negative controls; a throwaway image store on the scratch guest; capacity measured; the upstream drift re-run.
  • Phase 1 — real within-a-major upstream edges walked on guest 9202 through the product's own guarded Update, each seeded and read back through the app's own front door.
  • Phase 2 — the two database engines across a major, through the real Update button.
  • Phase 3 — the bad days, B1–B9.
  • Phase 4 — the morning after.
  • Phase 5 — teardown, three layers, plus Gitea.

What shipped

  • app-catalog-felhom.eu @4463243f2e09 — TEST CODE ONLY: four new harness fixtures and seven new edges (U1–U7). No template changed; no image: line moved. Gates green; CI job 830 = success.
  • felhom.eu — this report, the audit, the evidence, the register rows, the architecture updates, and one correction to update-arc-gaps-2026-09-21/00-api-recipe.md (the app page is /apps/<n>, not /app/<n>) and one FIX to unattended-caller.py (R-623).
  • No controller, agent or hub code was written. The brief forbade it and none was needed.

What is owed

The live catalog

Never touched with a broken, dummy, cross-repo or engine-major reference — not once, not for thirteen minutes. Its main moved only for the harness commit above, which changes scripts/ and zero image: lines; the teardown diff proves every image: line identical to the drill copy.